Menu

Monthly Archives: January 2017

Thanks, Obama: NSA to stream raw intelligence into FBI, DEA and pals

security update

security update

Shadow Brokers spew Windows hack tools after exploit auction flop

Type: Vulnerability. Microsoft Windows LSASS is prone to a denial-of-service vulnerability; fixes are available.

iPhone hacking biz Cellebrite hacked
Marie Moe on Medical Device Security
Pacemakers patched against potentially lifethreatening hacks
News in brief: new address system; fingerprint theft fears; facial recognition and chips, please
ShadowBrokers Bid Farewell, Close Doors
Hamas Compromised Dozens of IDF Soldiers’ Phones Using Seductive Female Images

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

WordPress 4.7.1 Fixes CSRF, XSS, PHPMailer Vulnerabilities

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Worm.

Security hardened, pah! Expert doubts Kaymera’s mighty Google’s Pixel
Insurer hit with fine after unencrypted NAS stolen
Beware new WhatsApp scam offering “free internet without Wi-Fi”

The number of scams spreading through the messaging app WhatsApp keeps on increasing, reports Lucas Paus. And there’s already a new one in 2017. The post Beware new WhatsApp scam offering “free internet without Wi-Fi” appeared first on WeLiveSecurity

Brother-and-sister duo arrested over hacking campaign targeting Italy’s bigwigs
43% off Microsoft Wireless Desktop 900 Keyboard and Mouse Bundle – Deal Alert
Russia ‘also hacked RNC’ – but not Trump’s campaign
Vawtrak malware spread via toxic Word documents is still a thing apparently
Flashing a peace sign in selfies could lead to identity theft, scientists warn
Honeytraps used to infect Israeli soldiers’ smartphones with spyware
Users reporting Electronic Arts (EA) servers are doing
Windows 10’s privacy dashboard aims to tackle data concerns
Fast Flux networks: What are they and how do they work?

The term Fast Flux can refer to networks used by several botnets to hide the domains used to download malware or host phishing websites, says Josep Albors. The post Fast Flux networks: What are they and how do they work? appeared first on WeLiveSecurity

Hacker Steals 900 GB of Cellebrite Data
Exitmap – Tor Exit Relay Scanner
Peace-sign selfie fools menaced by fingerprint-harvesting tech
Crims shut off Ukraine power in wide-ranging anniversary hacks

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

LinuxSecurity.com: New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New gnutls packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

Docker swings door shut on privilege escalation bug

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-8605

Donald Trump finally believes Russia hacked the DNC
Google Cloud unlocks key achievement

LinuxSecurity.com: update to 3.2.10.RELEASE, fix CVE-2016-9879

LinuxSecurity.com: fix CVE-2016-8741 (rhbz#1409836,1409835)

LinuxSecurity.com: Update to the latest upstream release 1.3.2, also with some security fixes (seebug #1193445 from the native flac package).

LinuxSecurity.com: Security fix for CVE-2016-8605

security update

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Professionally designed ransomware Spora might be the next big thing
Buggy Domain Validation Forces GoDaddy to Revoke Certs
Hacker siblings arrested for targeting Italian elite – infecting 20k emails
Cloudflare Shares National Security Letter It Received in 2013
ShadowBrokers Selling Windows Exploits, Attack Tools
News in brief: Telegram crack “fake”; superuser passwords leaked; election systems “critical infrastructure”
How Blockchain Can Revolutionize Personal Data Storage?
Second Try at Windows LSASS Patch Addresses Vulnerability
Spammers Revive Hancitor Downloader Campaigns
Trump: It was probably Russia that hacked the DNC, Clinton campaign
Beware phishing scams in Amazon listings
Notorious Shadow Brokers’ Group Now Selling Windows Hacking Tools
Digital video recorder installers master password list ‘leaked’ – claims
Airline passengers’ bookings and info leaked by boarding gate displays
Thousands of MongoDB databases compromised and held to ransom
GoDaddy revokes digital certificates improperly validated due to bug
Debugging a kernel in QEMU/libvirt
Hello Kitty, Goodbye database containing 3.3 million users credentials
Your data is being held for ransom. Now what?
GCHQ feeds first crop of infosec startups to Cyber Accelerator
LA College Hit By Ransomware: Pays $28,000 to Unlock Files
US Navy runs into snags with aircraft carrier’s electric plane-slingshot
CES: IoT security comes of age

For years, IoT security seemed like solving a problem that didn’t exist. Not anymore says ESET’s Cameron Camp, who was at this year’s CES. The post CES: IoT security comes of age appeared first on WeLiveSecurity

How White Hat hackers do bad things for good reasons
Families of ISIS victims sue Twitter for being ‘weapon for terrorism’
Oh Britain. Worried your routers will be hacked, but won’t touch the admin settings
How to secure MongoDB – because it isn’t by default and thousands of DBs are being hacked
Pay the ransom? You won’t get your data back
British Hadoop security startup expands to New York to land big investor

LinuxSecurity.com: Multiple vulnerabilities have been found in phpMyAdmin, the worst of which could lead to arbitrary code execution.

LinuxSecurity.com: Flex might generate code with a buffer overflow making applications using such scanners vulnerable to the execution of arbitrary code.

LinuxSecurity.com: A vulnerability has been found in Vim and gVim concerning how certain modeline options are treated.

LinuxSecurity.com: A vulnerability in vzctl might allow attackers to gain control over ploop containers.

LinuxSecurity.com: A heap-based buffer overflow in c-ares might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in 7-Zip, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in BIND might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in phpBB, the worst of which may allow remote attackers to inject arbitrary web script or HTML.

LinuxSecurity.com: Multiple vulnerabilities have been found in PgBouncer, the worst of which may allow an attacker to bypass authentication.

LinuxSecurity.com: Multiple vulnerabilities have been found in Botan, the worst of which might allow remote attackers to obtain ECDSA secret keys.

New Windows 10 privacy controls: Just a little snooping – or the max

LinuxSecurity.com: Gentoo’s NGINX ebuilds are vulnerable to privilege escalation due to the way log files are handled.

LinuxSecurity.com: Multiple vulnerabilities have been found in Expat, the worst of which may allow execution of arbitrary code.

Sundown exploit kit weaves Edge hack hole
Ansible patches ‘own the farm’ vulnerability
EMC slings patch at remote hack nonce-nse
Juniper warns: Borked upgrade opens root on firewalls

Risk Level: Very Low. Type: Trojan.

Brazilian Gov’t Twitter account mistakenly posts social media passwords
US Intel: Russia hacked Republican groups during election
Adobe patches critical flaws in Flash Player, Reader, and Acrobat
Netflix users targeted by credit card phishing scheme
Microsoft Issues Record Low Number of Patch Tuesday Bulletins
It’s now 2017, and your Windows PC can still be pwned by a Word file